Breaking
SecurityDeveloping Story

Cyberattacks Cost Firms $52,000 on Average

Hiscox report finds 29% of organizations hit by cyberattacks in the past year, with average costs of $52,000 and 32.8 hours of downtime.

··2 hours ago·4 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

When a cyberattack lands, the damage isn't confined to a single system. It ripples through operations, finances, and the workforce itself. A new global study from insurer Hiscox puts hard numbers on that ripple effect, showing that nearly a third of organizations have absorbed at least one successful attack in the past 12 months—and the fallout reaches far beyond the IT department.

Nearly a third hit in 12 months

The Hiscox Cyber Readiness Report 2026 found that 29% of organizations globally suffered at least one successful cyberattack over the previous year. Those victims didn't just face a single event; on average, they reported four incidents during that period.

Geography played a role in who got hit. UK-based firms were most likely to experience an incident, with 38% reporting successful attacks. US organizations were least likely, at 20%.

The report, published on September 15, draws on a survey of 6,800 security decision-makers across the UK, Europe, and the US.

Average incident cost: $52,000

Cyber incidents during the past 12 months cost organizations around $52,000 on average. But that global figure masks wide variation. The average cost of an incident was highest in Italy, at $134,138.

The financial toll isn't the only measure of impact. The global average downtime following an incident was 32.8 hours, according to the study. That's more than four full working days of disrupted operations.

Downtime means more than locked computers

Keven Knight, CEO of Talion Cyber Security, said the findings should serve as a wake-up call for business leaders.

“Downtime doesn’t just mean being locked out of computers, it means disruption to service, disruption to employees and their ability to perform their jobs, plus disruption to customers because they are unable to access the services or goods an organization provides to them,” he commented.

— Keven Knight, CEO of Talion Cyber Security

Knight added: “Every second of downtime costs the business money. This is when cyber has a very tangible impact on organizations and it is something board members and business leaders should never overlook.”

Growth, staffing, and reputation take hits

The study highlighted the extent to which cyber incidents can negatively impact strategic and growth opportunities. Among cyberattack victims:

  • 32% reported delays to growth and expansion or new business initiatives
  • 31% cited increased staffing or external expertise costs
  • 30% said there was a negative impact on financial performance, valuation or credit rating
  • 29% reported losing business opportunities or partnerships
  • 28% were impacted by financial penalties
  • 26% suffered negative publicity

These figures show that the consequences of an attack extend well past the immediate remediation effort. They touch hiring budgets, revenue forecasts, creditworthiness, and the ability to win new work.

Human toll: burnout and toxic culture

The Hiscox report also highlighted the human impact of cyber incidents. Over two-thirds (69%) of victims reported employee burnout, high stress, or a toxic workplace culture following a cyberattack.

That statistic points to a dimension of cyber risk that often goes unmeasured in boardroom discussions: the strain on the people who have to respond to and recover from an incident. When staff are already stretched, an attack can push teams past their limits.

Businesses invest $51,000 a year in resilience

In response to growing threats, businesses are investing an average of around $51,000 a year in strengthening their cyber resilience, according to the study.

That investment breaks down into several areas:

  • 62% updating employee cybersecurity training
  • 55% hiring additional cybersecurity personnel
  • 51% purchasing new software and tools

Additionally, 32% of respondents said their organization is linking executive compensation or performance metrics directly to cybersecurity outcomes. That's a notable shift: tying pay to security results can sharpen executive attention on risk.

AI security moves to the front burner

The insurer also reported that businesses are taking steps to improve the security of AI tools being deployed in their environments. These include:

  • 33% upskilling employees in AI and cybersecurity
  • 33% expanding AI awareness and training programs
  • 32% reviewing cyber insurance arrangements to ensure AI risks are covered
  • 31% planning regular AI audits

“Businesses are less concerned about speculative future AI scenarios than practical risks that already exist today, including corrupted training data, vulnerable third-party tools and reduced human oversight,” Hiscox wrote.

What the numbers mean for businesses

The Hiscox data suggests that cyber risk is no longer a peripheral IT concern. With nearly a third of organizations hit in a year, an average cost of $52,000 per incident, and 69% of victims reporting burnout or toxic culture, the consequences are operational, financial, and human.

For business leaders, the implication is that resilience spending—averaging $51,000 a year—may need to be weighed against the potential for far larger losses, including lost growth, penalties, and reputational damage. The finding that 32% of organizations now link executive pay to cyber outcomes could signal a shift in accountability, pushing security higher on the board agenda.

As AI tools become more embedded in operations, the practical risks Hiscox identifies—corrupted training data, vulnerable third-party tools, reduced human oversight—are ones that exist today, not in some distant future. Organizations that treat these as current operational risks rather than speculative ones may be better positioned to avoid the downtime, cost, and human strain that follow a successful attack.

#hiscox#cyberattack cost#downtime#cyber resilience#employee burnout#ai security

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories